"Authentication" and "Authorization" come up in every discussion of web system design and security. Their names are similar, so they often get confused, but their roles are clearly different.
If an engineer mixes them up when designing a system, it can lead to serious security risks. Here is a summary of how they differ and how they relate.
In short
In a single sentence:
- Authentication: verifying who the user is
- Authorization: deciding what the user is allowed to do
1. Authentication
Authentication is like presenting an ID card. It is the process by which the system checks, "Is the person accessing me really who they claim to be?"
- Purpose: identifying the user
- Examples:
- Logging in with an email address and password
- OAuth login using a Google or GitHub account
- Biometric authentication with a fingerprint or face
- Result: establishing that "the one sending this request is User A"
2. Authorization
Authorization is the granting and checking of permissions. It determines which operations (view, edit, delete, and so on) a particular user is allowed to perform on a particular resource.
- Purpose: access control
- Examples:
- "Only administrators can press the delete-user button"
- "Even when logged in, you cannot view someone else's private diary"
- "Only users on a paid plan can use the advanced analytics features"
- Result: deciding that "User A may (or may not) delete this data"
How authentication and authorization relate
In a typical application, processing happens in this order:
- Authentication: identify the user ("You are User A, right?")
- Authorization: check the identified user's permissions ("User A is not an administrator, so deletion is forbidden")
Successful authentication does not mean authorization is unnecessary. If you skip authorization checks on the assumption that "they're logged in, so it's safe," you end up with privilege escalation vulnerabilities, such as a regular user being able to call an administrator's API.
Summary
- Authentication is the identity check for opening the door.
- Authorization is the permission for what you may touch inside the room.
Designing these two as clearly separate concerns is the first step toward building secure applications.